I Showed ChatGPT My Fitwatch. It Asked How I'd Like to Fit Adverts Into My Chat.
Quick note before I start. The facts here are theirs, taken straight from OpenAI's own published Ads FAQ. What I make of those facts is mine. You'll know the difference as you read, and you can draw your own line.
I had a bit of a strange morning.
It started with me losing the charger for my watch. And because I am as stubborn as I am, I spent the better part of three hours tearing the house apart looking for it. Turned up nothing. Well, nothing useful. I found a charger, wrong one, an old model, and somehow finding the useless one deflated me more than finding nothing would have.
The whole time, I'd been messaging ChatGPT about it. Play by play. At one point I was trying to MacGyver a fix (yes I'm old), asking whether I could stretch the pogo pins with a coin or some tinfoil to get it charging. It talked me out of it. Told me, more or less, don't go making things hot that aren't meant to get hot. Fair enough.
Eventually I remembered a neighbour of mine has the same watch. Sent him a WhatsApp he said come over, charge it, no problem. Good man, spent far too much time talking about the rugby, and not enough time helping his wife... I suspect that was his duck and cover equivalent!
Once it finally had some juice (orange) back in it, I put it on and snapped a photo of it there on my wrist, then sent it off th ChatGPT. Nothing deep. Just "it lives."
And within about three seconds, this popped up.

I had to stand back for a second. Woah! What is happening here? I had never had this happen in any other LLM before.
The thing that had been helping me solve my stupid little problem all morning, that knew the whole saga play by play, had just stopped being a helper and started being a billboard.
Let me tell you.
Now, before anyone rolls their eyes, I know personalised ads are not new. Everyone does them. Google, Meta, your supermarket loyalty card, all of it. I am not naive about it, and I am not here to clutch pearls about the existence of targeted advertising.
That is not what stopped me.
What stopped me was the source. It is one thing for a search engine to guess what I want from what I typed into a box. It is another thing entirely when the profile is built out of the conversation I have been having, all morning, with something that talks back like a mate.
The ads are old. The intimacy of where they come from is new.
"Private" is doing a lot of work
So I went and read OpenAI's Ads FAQ. The whole thing. And the more carefully you read it, the more you notice one word working overtime.
Private.
"Privacy is not something that I'm merely entitled to, it's an absolute prerequisite.", Marlon Brando
OpenAI says your conversations stay private. They say it plainly, more than once. They tell you advertisers never get your chats, your history, your memories, your name, or your email. They even list "Conversation privacy" as a founding principle.
Sounds airtight.
Then, further down the same page, they explain how personalised ads actually work. The signals used to pick your ads include your current chat thread, "including personalised model responses." They include your past chats and memory.
Read those two sections back to back and the trick shows itself.
Both statements are true. Together, they are a sleight of hand.
"We don't share your conversations" is answering a question nobody was worried about. Of course the grocery brand doesn't get a transcript of your chats. The question that actually matters is the one the reassurance is built to distract from.
Does OpenAI read what you say to decide what you get sold?
Yes. By their own description, yes.
They are not selling your conversations. They are mining them in-house to target you, then telling you your conversations are private because the mining happens on their side of the wall.
That is the whole move. The word "private" describes the data's distance from advertisers. It does not describe its distance from the ad engine. Those are two completely different things, and the FAQ lets you believe the first one covers the second.
It doesn't.
The one promise you are not allowed to check
Read the FAQ and one claim gets repeated like a drumbeat. Ads do not influence answers.
They say it four different ways. Ads run on separate systems from the chat model. Advertisers cannot shape, rank, or alter responses. They make it a founding principle and call it "Answer independence."
Here is the thing. That is the single most important sentence in the entire document. And it is the one thing you have absolutely no way to verify.
Everything else in the FAQ, you can test. You can see the ad is labelled. You can watch it sit below the response. You can toggle the settings. But whether the ad engine is truly walled off from the model that answers you? You cannot see that. You cannot audit it. You are taking it entirely on their word.
And their word is worth exactly what it is worth. Which is to say, until there is an independent way to check it, it is a promise, not a fact.
Now hold that next to something else they wrote. When they list the signals used to personalise your ads, one of them is your current chat thread, "including personalised model responses."
Read that slowly. The model's answers to you are an input to the ad system.
So the answers do not shape the ads, they tell us. But the answers absolutely feed the ads, they also tell us. Those two things are allowed to both be true at once, and OpenAI is asking you to hold the line between them on faith.
Maybe the wall is real. I hope it is. But the whole arrangement now rests on trusting that the company selling the ads has perfectly separated the part that sells from the part you confide in.
And you will never be able to check whether they did.
They are guessing your age, and calling it safety
There is one line in the FAQ that most people will skim straight past. I want to stop on it.
They say ads will not appear in accounts where a user tells them, "or we predict," that they are under 18.
Predict.
Sit with that word. To predict your age, they have to be running some kind of behavioural guesswork on you. Reading your patterns. Your language. What you talk about, how you talk about it, when you are online. They are building a quiet profile of you and using it to estimate how old you are.
And here is the clean problem with that. It has nothing to do with anyone's identity or how they see themselves. It is much simpler than that.
Inference is not verification.
A system that guesses your age from behaviour cannot actually know who is on the other end of the screen. I am a forty-year-old man. On a given day my signals might look like a teenager's. A teenager's might look like mine. The guess will be wrong in both directions, constantly, because it is a guess.
So a system like this does two things at once, both bad. It will wrongly flag some adults as kids. And far more seriously, it will wave some kids through as adults.
That is not a safety feature. That is a profiling system wearing a safety feature's clothing.
And the timing matters. Regulators, the UK in particular, are pushing hard right now for what they call "highly effective age assurance" online. Behavioural inference is close to the opposite of that. It is age assurance by vibes.
The part that should sit with you is this. To decide whether to show you an ad, OpenAI has decided it needs to guess how old you are.
Which means the profiling is already running. The ad is just the first thing they have admitted to using it for.
The small print that quietly undoes the friendly words
Two smaller things before I wrap up. They are the same species as everything above. The friendly verb, and the actual behaviour, not quite matching.
The first is deletion. They tell you that you can clear the data used for ads at any time. Sounds instant. Read the detail, and clearing it means it stops being used to target you now, but it sits on their servers for up to thirty days before it is actually removed.
So "clear at any time" really means "stop using now, delete within a month." Not the same as gone.
The second is who gets to walk away cleanly. Ads are on the free plans. The paid tiers, Plus and Pro, are ad-free. So the way to fully escape the ad engine reading your chats is to pay for it.
Privacy from the targeting is not a right here. It is a feature. If you can afford the subscription, you are a customer. If you can't, you are the inventory.
Where they actually got it right
Now, I am not here to pretend OpenAI did all of this in bad faith, because they didn't. There are a couple of things in here they genuinely got right, and it would be dishonest of me not to say so.
They keep ads away from the stuff that matters most. No ads near personal health. No ads near mental health. No ads near politics. That is a real line, and plenty of ad companies would not draw it. Credit where it is due.
They also give you a way out that does not cost money. You can switch to a free version with no ads. The catch is lower message limits and fewer tools, so you pay in convenience instead of cash, but the option is there, and it is more than a lot of platforms offer.
So this is not the worst version of ad-supported AI. It might even be one of the more careful ones.
And that is exactly why the sleight of hand in the wording is worth pointing at. When a company is clearly trying to do this thoughtfully, the spots where the words still don't match the mechanism are the spots worth watching closest.
So, back to my watch
I got it charged. I got my "it lives" moment. And in the three seconds after I hit send, the thing I had been talking to all morning asked me to choose how I wanted to be sold to.
Nothing about that is illegal. Most of it, by their own account, is even fairly careful. Advertisers never see my chats. Ads stay away from the sensitive stuff. I can turn personalisation off, or pay to make the whole thing disappear.
But here is what I keep coming back to. The entire reason a tool like this is useful is that when you ask it something, it is answering you. Not steering you. Not sizing you up. Just helping.
The moment the thing you confide in is also the thing deciding what to sell you, something quiet shifts. Even if every promise in that FAQ holds perfectly. Even if the wall between the ads and the answers is solid steel. It still means that somewhere in there, the tool has started looking at you as a person to be monetised, and not only a person to be helped.
sent it a photo of my watch because I was happy I had sorted a stupid little problem. It saw an opportunity.
That is the whole thing, really.
"The cost of a thing is the amount of life which is required to be exchanged for it." — Henry David Thoreau
About the Author
Clayton Bax is an independent security researcher, technologist and writer with a particular interest in privacy, artificial intelligence, human-computer interaction and the unintended consequences of emerging technologies. His work sits at the intersection of technical analysis and human stories, with an emphasis on documenting where the evidence begins and, perhaps more importantly, where it ends.
Contact: ONYX Digital Intelligence OPFS Probe Research X: @BaximusCyber85
If this article resonates with you, or if you've observed similar behaviour in modern AI systems, I'd be delighted to hear from you. The fastest way to reach me is through my published work and associated contact channels.